VYPR

Tiki Wiki CMS

by Tiki

CVEs (6)

  • CVE-2025-34113HigJul 15, 2025
    risk 0.60cvss epss 0.02

    An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET parameter in `tiki-calendar.php`. When the calendar module is enabled and an authenticated user has permission to access it, an…

  • CVE-2016-10143HigJan 20, 2017
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner URL field.

  • CVE-2020-8966MedApr 1, 2020
    risk 0.42cvss 6.5epss 0.01

    There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a…

  • CVE-2024-47918MedDec 30, 2024
    risk 0.40cvss 6.1epss 0.00

    Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

  • CVE-2016-9889MedDec 23, 2016
    risk 0.40cvss 6.1epss 0.01

    Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don't have the input sanitized, related to tiki-setup.php and article_image.php. The impact is XSS.

  • CVE-2024-46879MedMar 23, 2026
    risk 0.35cvss 5.4epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive…